Submit a Story      Security   FAQ    Resources    Certification    Links    Calendar    Forum    Polls    Search      
User Functions
:

:

Don't have an account yet? Sign up as a New User
Lost your password?

What's New
STORIES
No new stories

COMMENTS last 2 days
No new comments

TRACKBACKS last 2 days
No new trackback comments

LINKS last 2 weeks
No recent new links


Who's Online
Guest Users: 4

Live Novell Chat
Live Novell Chat

Topics
Home
Contracting (2/0)
FAQ (1/0)
NetWare (49/0)
Certification (30/0)
NDS/eDir (19/0)
Administration (78/0)
GroupWise (112/0)
Linux/Open Source (294/0)
Resources (20/0)
General News (806/0)
Security (235/0)

Poll
What do you think of the new Novell support changes? I encourage you to leave your comments on this!
I like it, brings Novell's support in line with other companies such as Cisco
I do not like it
Novell is blooming crazy, this is going to push customers, IT people, and consultants away from Novell even further!
I do not care either way
Results
49 votes | 0 comments

Poll
What Version of ZENworks are running?
ZCM (10)
Zen 7
Zen 6
Zen 4
Zen 3
Zen 2
Zen 2 starter pack
Zen 1
Not running Zen
Results
122 votes | 0 comments


 The story behind the Novell hack story    
 Author:  Sean_
 Dated:  Thursday, October 06 2005 @ 10:53 PM EDT
 Viewed:  796 times  
General NewsBy Dave Kearns

There were a number of news stories last week about Novell's internal servers, including one posted at NetworkWorld.com under the headline "Novell server hacked."

It seems a security consultant in Virginia discovered that a client's site had been "scanned" a number of times by a machine whose IP address was traced back to Novell. At this point, the stories start to get confusing.

Most of the printed stories refer to the Novell server by saying: "The hacked system appeared to be running a mail server for a gaming site called Neticus.com, and the main game Web page for Neticus.com was hosted on a separate server that also belonged to Novell." Both statements are wrong, according to Novell's PR and a search on Google cache.

The Neticus.com site was hosting a discussion board (with very limited membership) for some participants (who may all have been Novell employees) in the "World of Warcraft" game. There was no "game server." The compromised server was another one, which was currently not used for any particular activity. Both are considered lab or test servers and are outside the Novell corporate firewall. It's also unclear whether the discussion board was within the bounds of Novell's corporate terms of use policy.

Still, scanning other people's computers should be considered "bad" behavior.

There are other confusing aspects to this story, though. A search on the Neticus.com domain at Google reveals that, at least at some point, this domain hosted the "official" home of Brigham Young University Athletics. It's unclear if this was the actual domain BYU used, or was simply a mirror site set up without the university's knowledge. But it was active at least as late as last December.

The Neticus.com domain was registered by Novell back in 1998 (by a man named "Bruce Wayne," who knew the caped crusader toiled away in Provo?). It was set up (presumably by folks in Novell's IT department) as a "proof-of-concept": an ISP running entirely on NetWare. Novell employees who applied for them were given accounts on the server and allowed remote access. But the documents describing the server (found by digging through the Internet Archive) specifically say: "Neticus is not a production corporate remote access system, nor is it a production Web server. It is a development, testing and design lab."

While the testing was ended in 2000, evidently the server stayed up and many people had access. It's unclear (i.e., Novell isn't talking) when it was first used to host the gaming discussion, but it's something any of the account holders could have set up. The testers provided a full-service ISP to their clients, including (according to the Internet Archive documents):

* Dial-Up Internet Access - "We support analog modem speeds up to 56k (V.90) and ISDN. We have POPs in Orem/Provo and San Jose."

* E-Mail - "We support SMTP & POP3/IMAP4 e-mail clients. And for those who would rather not bother with a client at all, we offer WebMail."

* Web Browsing/Hosting - "In addition to vanilla Web browsing, we offer accelerated browsing via a proxy server, and we also host users' home pages."

* Usenet News - "Alternately described as godless anarchy and/or the ultimate expression of freedom of speech, Usenet News consists mainly of millions of college freshmen telling each other that they 'suck.'"

The technologies used on the server were listed as:

* NetWare 5
* BorderManager Enterprise Edition 3.5
* Netscape Enterprise Server for NetWare
* Novell Internet Messaging Server 2.1
* DNews for NetWare

My conclusion? With all of the changes and layoffs, Novell lost track of these servers and one or two (current or former) disgruntled employees took advantage. It's unfortunate, and a real black eye for a networking company, but it isn't a major story in the greater scheme of things.

The administrator of the Neticus ISP test, by the way, was listed as Grettir Asmundarson (a pseudonym) whose personal Web site describes "him" as "ne'er-do-well, sluggard, and wastrel" (but no mention of being a gamer). Grettir is also the listed author of the "Beige Papers", Novell IT's documentation of the company's upgrade to NetWare 5 and a very interesting read for network managers.

The top 5: Today's most-read stories

1. How to solve Windows system crashes in minutes

2. Nortel faces uphill battle

3. Cisco pushes new security software

4. WLAN QoS specification approved

5. Somebody's got to pick up the 'Net's tab

To contact Dave Kearns:

Dave Kearns is a writer and consultant in Silicon Valley. He's written a number of books including the (sadly) now out of print "Peter Norton's Complete Guide to Networks." His musings can be found here.




What's Related

Story Options
  • Mail Story to a Friend
  • Printable Story Format

  • Trackback

    Trackback URL for this entry: http://www.abend.org/trackback.php/StoryBehindNovellHack

    No trackback comments for this entry.
    The story behind the Novell hack story | 0 comments | Create New Account
    The following comments are owned by whomever posted them. This site is not responsible for what they say.